I have the mgmt0/0 port set up on my ASA for mamanement-only. (ip address 192.168.1.1/24) All works fine if I connect to it from a PC on 192.168.1.0/24 range. If I try to connect from a PC outside this range I cannot connect. The ASA tries to send the return traffic to my remote PC via the inside interface as this is where the route is. And since this return packet is for an established connection that did not come in on the inside interface, I presume the ASA drops it. If this port is acting like a host device should there not be a default route command specific to that interface.